Redhat Alert
2978Warning Date
Severity Level
Warning Number
Target Sector
23 February, 2023
● Critical
2023-5474
All
Red Hat has released security alerts to address several vulnerabilities in the following product:
- Red Hat Enterprise Linux for ARM 64 8 aarch64
- Red Hat Enterprise Linux for ARM 64 9 aarch64
- Red Hat Enterprise Linux for IBM z Systems 8 s390x
- Red Hat Enterprise Linux for IBM z Systems 9 s390x
- Red Hat Enterprise Linux for Power, little endian 8 ppc64le
- Red Hat Enterprise Linux for Power, little endian 9 ppc64le
- Red Hat Enterprise Linux for x86_64 8 x86_64
- Red Hat Enterprise Linux for x86_64 9 x86_64
- Red Hat OpenShift Container Platform 4.9 for RHEL 8 x86_64
- Red Hat OpenShift Container Platform for ARM 64 4.9 aarch64
- Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.9 for RHEL 8 s390x
- Red Hat OpenShift Container Platform for Power 4.9 for RHEL 8 ppc64le
An attacker could exploit these vulnerabilities by doing the following:
- Sandbox Bypass
- Denial of Service Attack
- Improper Authorization
- CSRF Protection Bypass
- Java Unsafe Deserialization
- Stored XSS
- Cross-site Request Forgery (CSRF)
- Sensitive Information Disclosure
- Lack of authentication mechanism in Git Plugin
- Arbitrary file read
- Remote Code Execution
The CERT team encourages users to review Red Hat security advisory and update the affected product: